A decommissioned hard drive can still hold every account number, loan file, and transaction record it ever stored, recoverable long after the device itself stops working. For a bank, credit union, or lending institution, that turns a bin of retired equipment into a live compliance exposure, not a maintenance task. Once that equipment leaves your building, the vendor handling it is responsible for protecting all of it, and your contract is the only thing that says how.

Every ITAD vendor contract includes language about secure disposal. That phrase can describe a fully documented, verifiable process, or it can describe nothing enforceable at all. The difference comes down to specifics: what standard the vendor names, what documentation they provide, and who’s liable if something goes wrong. The sections below cover what to require in writing.

Start With What the Regulators Expect

The FTC’s Safeguards Rule under the Gramm-Leach-Bliley Act requires a written information security program with administrative, technical, and physical safeguards. The Rule extends that responsibility to service providers: an institution has to take steps to ensure its vendors protect customer information too, not just its own internal systems. The amended rule added explicit disposal obligations, requiring secure destruction of customer information once it’s no longer needed for a legitimate business purpose.

Bank examiners look at this from a parallel angle. The FFIEC’s IT Examination Handbook evaluates whether an institution’s third-party relationships, including its ITAD vendor, are properly governed and risk-assessed. 

Reviewing third-party vendor relationships is a routine part of a bank exam. Examiners check whether an institution can show, in writing, how its vendors protect customer data, because a vendor with access to that data is treated as an extension of the institution’s own risk. Weak vendor oversight feeds directly into the Management component of a bank’s exam rating, and a poor rating can block new branches, new products, and acquisitions for years, and in some cases, trigger asset caps.

None of this requires drafting compliance standards from scratch. It requires naming the standards that already exist, such as NIST 800-88 for data sanitization, and writing them into the contract as requirements the vendor must meet, not just describe.

Require a Named Data Sanitization Standard

The contract should name the standard the vendor follows for every media type it touches. NIST Special Publication 800-88 is the benchmark most examiners and auditors recognize, and it defines three sanitization levels: Clear, Purge, and Destroy, each tied to the sensitivity of the data and whether the media will be reused or physically destroyed.

An effective vendor contract states which method applies to which asset class, including mobile devices, backup tapes, and solid-state drives, since SSDs require different handling than spinning disks to achieve true data irrecoverability.

Ask for the sanitization method in writing. A hard drive that’s been degaussed and one that’s been overwritten are both “destroyed,” but an examiner or forensic reviewer will want to know which method your vendor used and why it was the right one for that asset.

Certificates of Destruction

The contract should require a serialized Certificate of Destruction for each device, tying an asset tag or serial number. That documentation is what your compliance team pulls during an internal 

Certifications the Contract Should Require

A vendor’s marketing page listing certifications is not the same as a contractual commitment to maintain them. Require these directly in the agreement, with a clause obligating the vendor to notify you if any lapse:

  • NAID AAA Certification, which verifies destruction providers through scheduled and unannounced audits
  • SERI R2v3, covering responsible reuse, repair, and recycling practices
  • ISO 14001 and ISO 45001, for environmental management and workplace safety

Liability, Insurance, and What Happens If Something Goes Wrong

If a drive leaves your building unsanitized and the data on it gets exposed, insurance pays for the fallout. The contract should require the vendor to carry cyber liability and errors-and-omissions coverage at limits that match the scale of your data exposure, not a generic minimum. It should also include a breach notification clause with a specific timeline, since your own regulatory reporting clock starts from the moment you learn about an incident.

Indemnification language matters here too. If a vendor’s downstream subcontractor mishandles equipment, your contract should make clear who’s financially responsible for the fallout, and it should restrict subcontracting of data-bearing assets without your prior written approval.

Reporting That Matches How Your Institution Operates

Beyond destruction records, the contract should require monthly financial reconciliation on any assets sold for revenue recovery, itemized reporting on quantities and disposition method for every batch processed, and portal access so your team can pull records without submitting a request and waiting on a reply.

Institutions juggling SOX, SEC, or FINRA record-retention holds also need a documented process for flagging assets subject to litigation or regulatory hold before destruction proceeds, since a routine ITAD pickup can inadvertently destroy records you were legally required to keep.

The Contract Is the Control

If your current ITAD vendor contract doesn’t specify how data is destroyed, verified, and documented, it’s time to look somewhere else. If you’re evaluating ITAD vendors, reach out to TAMS Solutions. Every contract we write specifies named destruction methods, per-device documentation, live certifications, and effective reporting.

Ready to Protect Your Data?

Ready to safeguard your assets and the environment? Request a quote today and discover how TAMS can elevate your IT lifecycle management.

Request a Quote
TAMS Logo